Security & data posture

Enterprise buyers need a clear answer to where data lives, who can see it, and how closure records stay trustworthy — even while the product is early.

Concept

Honest early-stage posture

We do not claim certifications we have not earned. This page explains how CADS handles workspace data today, what is on the roadmap, and where to read the legal detail in our Privacy policy.

Concept

What lives in CADS

CADS stores investigation and closure records for your workspace — not a copy of your entire ITSM.

  • Account identifiers from your sign-in provider (for example email and name).
  • Case and decision content you enter: reasoning, alternatives, evidence links, ownership, timestamps.
  • Workspace closure policy (Guardrail or Enforced), closure evaluations, and soft-exception records.
  • Integration metadata needed to link tickets and evaluate closure — tickets themselves stay in Jira or ServiceNow.
Pattern

Encryption

  • Data in transit is protected with TLS for the web application and API.
  • Data at rest is encrypted by the hosting and database platform we run on; ask us for the current region and provider details during a pilot.
  • Evidence is typically linked by URL rather than duplicated as bulk file stores inside CADS.
Application

Authentication & access control

  • Today: sign-in via supported identity flows (for example Google or email one-time codes) as offered in the product.
  • Workspace membership and roles gate who can change policy, document exceptions, and work cases.
  • SSO / SAML for enterprise IdPs is on the roadmap — available to discuss in pilot scoping rather than as a self-serve toggle today.
  • RBAC continues to deepen with workspace administration; current controls focus on team membership, policy ownership, and exception authority.
Application

Audit trail & retention

  • Closure evaluation, decisions, and soft exceptions form an append-oriented trail intended for managers and auditors.
  • Audit-oriented export is part of the product story for regulated teams — ask during pilot for the current export shape.
  • Retention follows your workspace and our Privacy policy; we do not silently rewrite history to make a closed case look cleaner after the fact.
Concept

Security questions

For questionnaires, region preferences, or SSO timing, write to hello@cadslab.com or use Get in touch from the site. We would rather answer plainly than overclaim.

Ready to apply this?

Start a decision in CADS →

Reviewed by: Cadslab · Product

Published: 2026-08-01 Updated: 2026-08-01

Last reviewed: 2026-08-01

Was this page useful?